#Define IPsec on network interface eth2
set vpn ipsec ipsec-interfaces interface eth2

#Enable network access translation
set vpn ipsec nat-traversal enable

#Allow every ip-address to initially try to use the IPsec service
set vpn ipsec nat-networks allowed-network 0.0.0.0/0

#Define ip-address the service is listening on
set vpn l2tp remote-access outside-address 176.58.92.230

#Define services Internetgateway
set vpn l2tp remote-access outside-nexthop 176.58.92.1

#Range of ip-addresses clients get
set vpn l2tp remote-access client-ip-pool start 10.0.0.100
set vpn l2tp remote-access client-ip-pool stop 10.0.0.120

#Service must use the pre-shared key "test"
set vpn l2tp remote-access ipsec-settings authentication mode pre-shared-secret
set vpn l2tp remote-access ipsec-settings authentication pre-shared-secret test

#Users have to provide their names and passwords too
set vpn l2tp remote-access authentication mode local

#Set username and password for client to "test" and "test"
#Arbitrary users with corresponding passwords can be set
set vpn l2tp remote-access authentication local-users username test password test

#Set maximum package size for OSI layer three
#Needed for clients running on Microsoft Windows operating systems
set vpn l2tp remote-access mtu 1492     

#Set domain name servers for the service to use Googles DNS servers
set vpn l2tp remote-access dns-servers server-1 8.8.8.8       
set vpn l2tp remote-access dns-servers server-2 8.8.8.9

#Commit and save changes to take effect
commit
save
